Effective Date: August 1, 2026
This App is not a medical device and does not provide medical advice, diagnosis, or treatment. The App is intended for informational, educational, research, or wellness purposes only. Users should consult a qualified healthcare professional regarding any medical questions or conditions.
This Privacy Policy describes how LSU's Pennington Biomedical Research Center ("PBRC," "we," "us," or "our") collects, uses, maintains, protects, and discloses information through the Diabetes Clinic mobile application (the "App").
The App is intended for adults only. Users must be 18 years of age or older. The App is not directed to children, and PBRC does not knowingly collect information from anyone under 18. The App is offered only to users in the United States and is not intended for use outside the United States.
This Policy covers two categories of information:
Where information qualifies as PHI, the PHI provisions of this Policy control. Non-PHI information is governed by the general provisions of this Policy.
Depending on the App's function, PBRC may act as:
PBRC complies with applicable provisions of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule (45 C.F.R. Parts 160 and 164).
Depending on App design and use, PHI may include:
PBRC collects only the minimum necessary PHI required to operate the App.
This Policy's non-PHI provisions apply to:
Protected Health Information, if collected through the App, is governed exclusively by the PHI provisions of this Policy. Where information qualifies as PHI, the PHI provisions control.
PBRC may use PHI for purposes permitted by HIPAA, including:
PBRC uses non-PHI information to:
PBRC may disclose PHI:
PBRC does not sell PHI and does not use PHI for marketing without valid authorization when required.
Non-PHI information may be shared with:
The App may use limited tracking or analytics technologies for functionality and performance monitoring. These technologies do not replace or override HIPAA protections for PHI.
PBRC does not engage in cross-app tracking for advertising purposes.
PBRC maintains administrative, technical, and physical safeguards designed to protect information, including:
PBRC implements reasonable safeguards to protect non-PHI information from unauthorized access or disclosure.
Individuals have rights under HIPAA, including the right to:
We retain personal information and other user data collected through the Diabetes Clinic app for as long as your account remains active or as needed to provide the app's services. You may delete your account and the data associated with it at any time. Within the App on both iOS and Android, an account-deletion option directs you to instructions for deleting your account and associated data. You may also delete your account by signing in at https://penningtondiabetesclinic.com/ and selecting Delete Account. When you delete your account, deletion takes effect immediately, and your account and associated app data are permanently deleted.
Where a use or disclosure of your information requires your authorization, you may revoke that authorization at any time.
We may retain limited information after an account is deleted only when required by applicable law or when reasonably necessary for security, fraud prevention, resolving disputes, enforcing our agreements, or maintaining legally required medical or business records. Information retained for one of these purposes will be limited to what is necessary, will not be used for other purposes, and will be kept only for the period required by applicable law or for as long as the stated purpose requires. It will then be securely deleted or de-identified.
Medical records maintained separately by Pennington Biomedical or another health care provider, including records maintained in an electronic health record system, may be subject to legal and regulatory retention requirements and are not deleted with your app account. Such records will be retained only for the period required by applicable law and will be securely disposed of when that period ends. Questions or requests concerning those records may be directed to the HIPAA Privacy Officer using the contact information provided in this policy.
PBRC will provide breach notifications in accordance with HIPAA and applicable state law.
Certain information collected through this App may be linked to an individual user, such as when associated with an account, patient identifier, or contact information. Other information may be collected or processed in a de-identified or aggregated form that is not linked to an individual.
PBRC's App Privacy Details disclosures in App Store Connect accurately reflect whether data is linked or not linked to users. PBRC does not track users across apps or websites owned by other companies for advertising or marketing purposes, as defined by Apple's App Tracking Transparency (ATT) framework.
This App is distributed through third-party platforms, including the Google Play Store, which require additional user-facing disclosures regarding data collection, use, sharing, and security practices.
This Policy is intended to align with the disclosures provided in the Google Play Console Data Safety section for this App. PBRC discloses, in both this Policy and the Google Play Data Safety section:
PBRC makes reasonable efforts to ensure that disclosures are accurate, complete, and consistent across this Privacy Policy, the App, and platform-specific disclosures.
Nothing in this Policy limits PBRC's obligations under HIPAA or applicable state law. Where this Policy and platform-specific disclosures address the same data practices, PBRC intends that they be interpreted consistently.
PBRC may update this Privacy Policy from time to time. The Effective Date reflects the most recent revision. Continued use of the App constitutes acceptance of any changes.
JPL Technical Solutions is the official developer of the Diabetes Clinic app. Their responsibilities encompass the design, implementation, and ongoing enhancement of the app, ensuring a seamless and functional user experience. They are dedicated to maintaining the highest standards of security, app performance, and reliability to effectively serve the needs of users.